Skip to main content

X25519-only TLS ends for GHE.com on October 7

By Steven Van ·

Only GitHub Enterprise Cloud with data residency is affected, and only clients configured to offer X25519 alone; SSH is unaffected.

Starting October 7, 2026, GitHub Enterprise Cloud with data residency will stop accepting TLS connections from clients that offer only X25519 for key agreement. The affected endpoints will keep supporting the FIPS-approved P-256 (secp256r1) and P-384 (secp384r1) groups.

Most customers need to do nothing. Current browsers, operating systems, GitHub CLI releases and commonly used TLS libraries already support P-256. The change matters if an application, proxy, security appliance or TLS library is explicitly configured to offer only X25519. After October 7, those clients will be unable to establish HTTPS connections.

Before the cutoff, GitHub recommends three steps:

  • Update your operating system, runtime, GitHub CLI, proxy and TLS libraries to supported versions.
  • Remove any X25519-only configuration.
  • Make sure P-256 (secp256r1) is enabled. P-384 (secp384r1) can be enabled as well.

The change applies only to GitHub Enterprise Cloud with data residency. SSH connectivity is not affected. GitHub Support can help validate a TLS configuration.

GitHub
GitHub
Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.
View GitHub →

Read the original announcement →

Read X25519-only TLS ends for GHE.com on October 7 on Creators Toolbox